Share

FIRSTonline Banner

Cryptocurrency, massive Coldcard theft: up to $130 million in Bitcoin stolen. What happened?

The crypto world is in turmoil over the massive Coldcard wallet theft. A flaw hidden for years exposed thousands of Bitcoin wallets. Over $100 million was stolen, but the loot could be much higher. Here's what happened.

Cryptocurrency, massive Coldcard theft: up to $130 million in Bitcoin stolen. What happened?

Il The cryptocurrency world is in turmoil for a theft worthy of Arsène Lupin. Without breaking into safes, stealing devices or sending scam messages, one or more hacker groups would have managed to empty thousands of Coldcard digital wallets, considered among the most reliable systems for pProtect Bitcoins from the Internet.

The confirmed loot already exceeds 100 million dollars and could approach 130 million. This attack didn't directly affect Bitcoin, but it did hit one of the most sensitive points of the entire ecosystem: how the keys needed to access cryptocurrencies are created and stored.

Coldcard digital wallets emptied: what happened?

Between July 29th and the first days of August thousands of Bitcoin addresses linked to Coldcard devices were emptied through several coordinated wavesThe victims hadn't provided passwords, clicked on suspicious links, or installed malicious programs. In some cases, the devices were turned off, never directly connected to the internet, and stored in safes. One of the first investors to notice the attack was a Canadian citizen. In just seven minutes saw 18,25 Bitcoin disappear, worth approximately $1,15 million. Opening his wallet on July 29, he discovered that the various addresses had been drained one after another.

The first reconstructions had identified Over a thousand Bitcoins stolen in less than an hourAs the days passed, however, the toll grew.

Galaxy Research, the analysis center of the American financial company Galaxy Digital also specialized in the cryptocurrency market, has estimated at least 1.596 Bitcoins stolen from approximately 7.300 addresses. A fourth wave, not yet confirmed by a sufficient number of victims, could bring the total at 2.055 Bitcoin, for a value close to 130 million dollars. The figures remain provisionalSome owners may not have yet noticed the theft, while other suspicious addresses must be clearly linked to the attack.

Coldcard Theft: A Five-Year-Old Flaw Hidden

Hackers may not have breached the Bitcoin network and not even remotely “opened” the Coldcard devices. The problem was deeper and was located in the process with which some wallets created users' secret credentials. When a hardware wallet is configured, the device generates a series of words called seed phraseThis sequence represents the wallet's master key and allows it to be reconstructed even if the device is lost or broken. Who can trace the seed? can then control the Bitcoins stored within it.

To be sure, the sequence must be generated in a truly random way. In the Coldcard case, some versions of the program inside the device would have produced less unpredictable combinations than expected. It's as if a safe sold with millions of possible codes actually uses a much smaller set of combinations. vulnerability would have been introduced in March 2021, during the update of a library used by the firmware, i.e., the software that runs the device. Instead of the hardware random number generator, a weaker software procedure would have been activated.

For years, no one would have noticed that keys created by certain models could be easier to reconstruct. Attackers would therefore have analyzed the possible combinations on their computers until they find the correct credentials, without needing to steal or connect the victims' wallets.

I most exposed devices These would be the old Coldcard Mk2 and Mk3, but the problem also affects seeds generated on some Mk4, Mk5 and Coldcard Q before the corrective updates were released.

Coldcard Theft: The Artificial Intelligence Suspicion

Coinkite, the Canadian company that produces Coldcard, has speculated that the attackers may have used artificial intelligence tools to examine the firmware code and find the defect. Coldcard software is open source, so it can be publicly analyzed. This transparency allows independent experts to monitor it and report any problems, but it also offers the same opportunity to those looking for vulnerabilities to exploit.

Coinkite itself had used artificial intelligence to check the code a few weeks before the attack. According to the company, that analysis "did not detect this bug or anything serious."

Alex ThornGalaxy Digital's head of research, argued that the search for the flaw was "likely orchestrated with a complex linguistic model." There's no definitive proof yet, but the incident shows how artificial intelligence can become an important tool in the race between those who protect computer systems and those who attempt to breach them. Furthermore, once the vulnerability was made public, other groups may have begun searching for and emptying the wallets still exposed. The different patterns observed during the attack suggest that not all the thefts are necessarily attributable to the same perpetrator.

Why the case is destabilizing the crypto world

The Coldcard case is particularly serious because it affects one of the more deeply rooted beliefs among Bitcoin holders. “Not your keys, not your coins,” meaning “if you don't have the keys, you don't have the coins,” is the principle according to which leaving cryptocurrencies with a platform, bank, or other intermediary means not having full control over them. hardware wallet They were created specifically to allow investors to personally store the keys and keep them off the internet. The Coldcard case, however, demonstrates that having direct control doesn't automatically mean being safe.

The victims, in many cases, had followed all the normally recommended precautions. The weakness wasn't their behavior, but the way the device created the keys from the start. This was a risk impossible for a typical user to recognize. Self-storage offers greater control, but also transfers technical risks to the owner, which they often can't assess. The theft could therefore push some investors to bring their Bitcoin back to the exchange platforms, relying on professional operators or choosing financial instruments like ETFs, which allow exposure to cryptocurrency without storing it directly. These solutions also present problems. Relying on an intermediary means exposing yourself to the risk of bankruptcy, account freezes, or mismanagement. Storing Bitcoin yourself, on the other hand, requires trusting the device, its software, and the process used to create the keys.

No repercussions significant, at least for now, on the price of BitcoinThe cryptocurrency is holding around $63.535, up slightly by 0,11%, a sign that investors appear to have distinguished the Coldcard vulnerability from the security of the Bitcoin network.

Coldcard Theft: Update Doesn't Save Old Keys

Coinkite has published emergency updates for the devices involved, but install the new firmware is not enough To secure existing wallets. The update corrects the way new seeds are created, but it cannot secure previously generated ones. Owners of potentially exposed wallets must therefore update their device, create a completely new sequence of words, and transfer their bitcoins to new addresses.

The manufacturer recommends check your backup carefullyVerify the destination address and initially send a small test amount. Only after verifying the correct functioning of the new wallet should the remaining funds be transferred. According to Coinkite, users who added at least 50 random and secret dice rolls during setup may not be directly vulnerable. A long, unique, and difficult-to-guess BIP-39 password can also provide an additional obstacle to attackers. The company still encourages users to replace their old seeds.

About the 90% of stolen Bitcoins are still sitting on the addresses used by attackersUS authorities, analytics firms, and exchanges are tracking the movements on the blockchain, the public ledger on which transactions are recorded. The sums are large, their provenance is now known, and the addresses are monitored. Any attempt to transfer them through regulated operators could trigger checks and blockades.

The loot might therefore be difficult to spend, but the the damage has already been doneThe Bitcoin network did not collapse and its cryptographic protection was not broken. However, it was confidence in the tools has been hit used to store cryptocurrencies.

A nearly invisible theft, planned for years due to a software flaw and carried out without even getting close to the victims. A digital Arsène Lupin-esque heist that leaves the industry faced with an uncomfortable question: how secure can a safe really be if its secret code is already weaker than expected?

comments